Skip to main content

Configure Spoofing and Authentication Protections in Google Workspace

How to protect against email spoofing and impersonation attacks in Gmail.

Written by Kavi Harshawat
Updated over 2 weeks ago

Overview

Spoofing attacks impersonate your domain, employees, or Google Groups to trick users into trusting malicious emails. Enabling Gmail's spoofing and authentication protections helps detect and block these attempts before they reach users' inboxes.

Prerequisites

  • Super Admin access to the Google Admin console

  • Gmail Settings administrator privilege

Instructions

  1. Sign in to the Google Admin console

  2. Navigate to Apps > Google Workspace > Settings for Gmail > Safety

  3. Scroll to the Spoofing and authentication section and enable the following settings, configuring an action for each:

Protect against domain spoofing based on similar domain names — Detects incoming messages from domains that appear visually similar to your company's domains or aliases.

Protect against spoofing of employee names — Detects messages where the sender's display name matches a name in your Google Workspace directory but the email isn't from your domain.

Protect against inbound emails spoofing your domain — Protects against Business Email Compromise (BEC) messages pretending to be from your domain that aren't authenticated with SPF or DKIM.

Protect against any unauthenticated emails — Blocks messages that aren't authenticated by either SPF or DKIM from any domain.

Protect Groups from inbound emails spoofing your domain — Protects Google Groups from spoofed inbound emails. Can be applied to all groups or private groups only.

Once all settings are configured, click Save.

Note: For best results, ensure your domain has SPF, DKIM, and DMARC records configured. These email authentication protocols work alongside Gmail's spoofing protections to verify sender identity.

Did this answer your question?